CVE-2021-21900
published 2021-11-19CVE-2021-21900: A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dxf file can…
PriorityP345high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
2.46%
82.7th percentile
A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dxf file can lead to a use-after-free vulnerability. An attacker can provide a malicious file to trigger this vulnerability.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | librecad | < librecad 2.1.3-2 (bookworm) | librecad 2.1.3-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| librecad | libdxfrw | — | — |
| librecad | librecad | >= 0 < 2.1.3-1.3+deb11u1 | 2.1.3-1.3+deb11u1 |
| librecad | librecad | >= 0 < 2.1.3-2 | 2.1.3-2 |
| librecad | librecad | >= 0 < 2.1.3-2 | 2.1.3-2 |
| librecad | librecad | >= 0 < 2.1.3-2 | 2.1.3-2 |
| librecad | librecad | >= 0 < 2.1.3-1.2+deb10u1build0.20.04.1 | 2.1.3-1.2+deb10u1build0.20.04.1 |
| librecad | librecad | >= 0 < 2.0.9-2ubuntu0.1~esm1 | 2.0.9-2ubuntu0.1~esm1 |
| librecad | librecad | >= 0 < 2.1.2-1ubuntu0.1~esm1 | 2.1.2-1ubuntu0.1~esm1 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
librecad vulnerabilities
osv·2023-03-15·CVSS 7.8
CVE-2018-19105 [HIGH] librecad vulnerabilities
librecad vulnerabilities
Cody Sixteen discovered that LibreCAD incorrectly
handled memory when parsing DXF files. An attacker could
use this issue to cause LibreCAD to crash, leading to a
denial of service. This issue only affected
Ubuntu 16.04 ESM and Ubuntu 18.04 ESM. (CVE-2018-19105)
Lilith of Cisco Talos discovered that LibreCAD incorrectly
handled memory when parsing DWG files. An attacker could
use this issue to cause LibreCAD to crash, leading to a
denial of service, or possibly execute arbitrary code.
(CVE-2021-21898, CVE-2021-21899)
Lilith of Cisco Talos discovered that LibreCAD incorrectly
handled memory when parsing DRW files. An attacker could
use this issue to cause LibreCAD to crash, leading to a
denial of service, or possibly execute arbitrary code.
(CVE-2021-21900)
Albi
GHSA
GHSA-j7ww-g7m2-fpcg: A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2
ghsa_unreviewed·2022-05-24
CVE-2021-21900 [HIGH] CWE-416 GHSA-j7ww-g7m2-fpcg: A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2
A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dxf file can lead to a use-after-free vulnerability. An attacker can provide a malicious file to trigger this vulnerability.
OSV
CVE-2021-21900: A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2
osv·2021-11-19·CVSS 8.8
CVE-2021-21900 [HIGH] CVE-2021-21900: A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2
A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dxf file can lead to a use-after-free vulnerability. An attacker can provide a malicious file to trigger this vulnerability.
Ubuntu
LibreCAD vulnerabilities
vendor_ubuntu·2023-03-15·CVSS 7.8
CVE-2021-21899 [HIGH] LibreCAD vulnerabilities
Title: LibreCAD vulnerabilities
Summary: Several security issues were fixed in LibreCAD.
Cody Sixteen discovered that LibreCAD incorrectly
handled memory when parsing DXF files. An attacker could
use this issue to cause LibreCAD to crash, leading to a
denial of service. This issue only affected
Ubuntu 16.04 ESM and Ubuntu 18.04 ESM. (CVE-2018-19105)
Lilith of Cisco Talos discovered that LibreCAD incorrectly
handled memory when parsing DWG files. An attacker could
use this issue to cause LibreCAD to crash, leading to a
denial of service, or possibly execute arbitrary code.
(CVE-2021-21898, CVE-2021-21899)
Lilith of Cisco Talos discovered that LibreCAD incorrectly
handled memory when parsing DRW files. An attacker could
use this issue to cause LibreCAD to crash, leading to a
denial of se
Debian
CVE-2021-21900: librecad - A code execution vulnerability exists in the dxfRW::processLType() functionality...
vendor_debian·2021·CVSS 8.8
CVE-2021-21900 [HIGH] CVE-2021-21900: librecad - A code execution vulnerability exists in the dxfRW::processLType() functionality...
A code execution vulnerability exists in the dxfRW::processLType() functionality of LibreCad libdxfrw 2.2.0-rc2-19-ge02f3580. A specially-crafted .dxf file can lead to a use-after-free vulnerability. An attacker can provide a malicious file to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 2.1.3-2)
bullseye: resolved (fixed in 2.1.3-1.3+deb11u1)
forky: resolved (fixed in 2.1.3-2)
sid: resolved (fixed in 2.1.3-2)
trixie: resolved (fixed in 2.1.3-2)
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Multiple code execution vulnerabilities in LibreCAD
blogs_talos·2021-11-17·CVSS 8.8
CVE-2021-21898 [HIGH] Vulnerability Spotlight: Multiple code execution vulnerabilities in LibreCAD
Lilith >_> of Cisco Talos discovered this vulnerability.
Cisco Talos recently discovered three vulnerabilities in LibreCAD’s libdfxfw open-source library.
This library reads and writes .dxf and .dwg files — the primary file format for vector graphics in CAD software. LibreCAD, a free computer-aided design software for 2-D models, uses this libdfxfw.
TALOS-2021-1349 (CVE-2021-21898) and TALOS-2021-1350 (CVE-2021-21899) can trigger buffer overflows if an attacker tricks the user into opening a specially crafted DWG file, eventually allowing the attacker to execute code on the victim machine. TALOS-2021-1351 (CVE-2021-21900) works in a similar manner, but with a DXF file instead. Cisco Talos worked with LibreCAD to ensure that these issues are resolved and an update is available for affect
Talos
Vulnerability Spotlight: Multiple code execution vulnerabilities in LibreCAD
blogs_talos·2021-11-17·CVSS 8.8
CVE-2021-21898 [HIGH] Vulnerability Spotlight: Multiple code execution vulnerabilities in LibreCAD
## Vulnerability Spotlight: Multiple code execution vulnerabilities in LibreCAD
Lilith >_> of Cisco Talos discovered this vulnerability.
Cisco Talos recently discovered three vulnerabilities in LibreCAD’s libdfxfw open-source library.
This library reads and writes .dxf and .dwg files — the primary file format for vector graphics in CAD software. LibreCAD, a free computer-aided design software for 2-D models, uses this libdfxfw.
TALOS-2021-1349 (CVE-2021-21898) and TALOS-2021-1350 (CVE-2021-21899) can trigger buffer overflows if an attacker tricks the user into opening a specially crafted DWG file, eventually allowing the attacker to execute code on the victim machine. TALOS-2021-1351 (CVE-2021-21900) works in a similar manner, but with a DXF file instead. Cisco Talos worked with LibreC
https://lists.debian.org/debian-lts-announce/2021/12/msg00002.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RDI3HCTCACMIC7I4ILB3NRU6DCMADI5H/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZTIAMP7QJDKV4ADDLR4GVVX2TXYLHVOZ/https://security.gentoo.org/glsa/202305-26https://talosintelligence.com/vulnerability_reports/TALOS-2021-1351https://www.debian.org/security/2022/dsa-5077https://lists.debian.org/debian-lts-announce/2021/12/msg00002.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RDI3HCTCACMIC7I4ILB3NRU6DCMADI5H/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZTIAMP7QJDKV4ADDLR4GVVX2TXYLHVOZ/https://security.gentoo.org/glsa/202305-26https://talosintelligence.com/vulnerability_reports/TALOS-2021-1351https://www.debian.org/security/2022/dsa-5077
2021-11-19
Published